๐ต๏ธ RESEARCH & DEEP DIVES
-
OpenPanel before 2.3.0 vulnerable to unauthenticated SSRF via favicon and og endpoints
OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in its favicon and og endpoints.- Affects OpenPanel deployments running versions before 2.3.0
- Unauthenticated server-side request forgery (SSRF) vulnerability in the /misc/favicon and /misc/og endpoints
- Endpoints accept an attacker-supplied url parameter with insufficient validation
๐ Coverage: cve.threatint.com ยท ๐ via CVE ThreatInt
-
OpenPanel before 2.3.0 vulnerable to cross-tenant BOLA via report tRPC procedures
OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in its report tRPC procedures.- Affects OpenPanel deployments running versions before 2.3.0.
- The report.getLayouts and report.resetLayout tRPC procedures contain a cross-tenant broken object level authorization (BOLA) vulnerability.
- The procedures fail to scope dashboard queries to the requesting tenant, enabling cross-tenant access to dashboard data.
๐ Coverage: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Microsoft Confirms New Exchange Online Outage Delaying Emails from External Domains
Microsoft has confirmed a new Exchange Online outage that is delaying emails sent to and from external domains.- The outage affects Microsoft Exchange Online, one of the most widely used business email platforms.
- The incident, tracked as EX1467029, is causing delays for users sending and receiving email messages from external domains.
- Microsoft flagged the issue as a service degradation and first acknowledged the disruption on September 4, 2026.
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
-
Microsoft 365 Phishing Bypasses Direct Send Blocking via Blank SMTP Envelope Sender
Phishers are leaving the SMTP envelope sender blank to slip unauthenticated messages past Microsoft 365's Direct Send blocking.- Affects Microsoft 365 users and organizations relying on Direct Send safeguards to block unauthenticated inbound email.
- Phishing emails display a sender address that appears to belong to the recipient's own organization.
- The technique works by omitting the SMTP envelope sender entirely, which can let unauthenticated messages pass Direct Send blocking.
- It is an abuse of protocol behavior, not a Microsoft software flaw, so no CVE or patch is associated with it.
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
-
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges (one-liner) โ <https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/|BleepingComputer>
-
Exchange Online outage causes email delays, 'Server busy' errors (one-liner) โ <https://www.bleepingcomputer.com/news/microsoft/exchange-online-outage-causes-email-delays-server-busy-errors/|BleepingComputer>
-
Google warns of new Chrome zero-day flaw exploited in attacks (one-liner) โ <https://www.bleepingcomputer.com/news/security/google-warns-of-new-chrome-zero-day-flaw-exploited-in-attacks/|BleepingComputer>
-
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover (one-liner) โ <https://www.securityweek.com/12-year-old-postgresql-vulnerability-enables-database-server-takeover/|SecurityWeek>
-
Catch Raises $5 Million for AI Executive Assistant With Guardrails (one-liner) โ <https://www.securityweek.com/catch-raises-5-million-for-ai-executive-assistant-with-guardrails/|SecurityWeek>
-
VMware Workstation and Fusion Updates Patch Critical Vulnerability (one-liner) โ <https://www.securityweek.com/vmware-workstation-and-fusion-updates-patch-critical-vulnerability/|SecurityWeek>
-
Google Patches 6th Chrome Zero-Day of 2026 (one-liner) โ <https://www.securityweek.com/google-patches-6th-chrome-zero-day-of-2026/|SecurityWeek>
-
Nvidia Is Buying AI Platform Hugging Face for $13 Billion (one-liner) โ <https://www.securityweek.com/nvidia-is-buying-ai-platform-hugging-face-for-13-billion/|SecurityWeek>
-
Security Vulnerability in a Voting System (one-liner) โ <https://www.schneier.com/blog/archives/2026/09/security-vulnerability-in-a-voting-system.html|Schneier on Security>
-
AI Is Ending the Era of Hidden Vulnerabilities โ Are Vendors Ready? (one-liner) โ <https://www.darkreading.com/vulnerabilities-threats/ai-ending-era-hidden-vulnerabilities-are-vendors-ready|Dark Reading>
-
SQL Injection in TAC Information's GoldenHornImproper neutralization of speci... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-18198?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Username Enumeration in Menulux Software's Menulux PortalObservable response ... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-19080?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Plaintext Storage of User Credentials in Menulux Software's Menulux PortalPla... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-19051?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Authorization Bypass Critical POS Management Functions in Menulux Software's ... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-19043?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Stored XSS in Menulux Software's Menulux PortalImproper neutralization of inp... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-18957?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
snipe-it before 8.6.3 Authorization Bypass via Bulk Deletesnipe-it versions b... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-85617?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Snipe-IT before 8.6.2 Authorization Bypass via Checkout-AcceptanceSnipe-IT ve... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-85616?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayoutsOpenpanel befor... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-85615?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checkerOpenPanel bef... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-85614?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
OpenPanel Unauthenticated XSS via SVG Favicon ProxyOpenPanel before 2.3.0 con... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-85613?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
OpenPanel before 2.3.0 Remote Code Execution via chart formulasOpenPanel befo... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-85610?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Openpanel before 2.3.0 SSRF via Site Checker EndpointOpenpanel before 2.3.0 c... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-85609?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Grav before 2.0.19 Remote Code Execution via sort filterGrav before 2.0.19 (a... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-85604?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Grav Admin Plugin Path Traversal via Save As Language CodeGrav versions befor... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-85603?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication BypassThe Grav For... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-85602?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Grav Admin before 2.0.20 Cross-Site Scripting via marked.jsGrav Admin before ... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-85601?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Grav Admin before 2.0.21 Stored XSS via usernameGrav Admin (getgrav/grav-plug... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-85600?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parametersGrav Shor... (one-liner) โ <https://cve.threatint.com/CVE/CVE-2026-85599?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
I can't believe The Register ran my quote, lol - kudos. (one-liner) โ <https://cyberplace.social/@GossiTheDog/117212745759654125|@GossiTheDog@cyberplace.social>
-
If you work for Google or Microsoft in security, ask internally what the browser teams are doing about it. (one-liner) โ <https://cyberplace.social/@GossiTheDog/117212722433258360|@GossiTheDog@cyberplace.social>
-
Obvious point - browser makers (hi Google and Microsoft) should have this stuff built in. (one-liner) โ <https://cyberplace.social/@GossiTheDog/117212711615780511|@GossiTheDog@cyberplace.social>
โ ๏ธ